
Login Mandatory Pages Security & Risk Analysis
wordpress.org/plugins/login-mandatory-pagesLogin Mandatory pages is a WordPress plugin that allows you to make pages accessible for only logged in users.
Is Login Mandatory Pages Safe to Use in 2026?
Generally Safe
Score 85/100Login Mandatory Pages has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "login-mandatory-pages" v1.2 exhibits a strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points, coupled with the complete use of prepared statements for SQL queries, indicates a robust adherence to secure coding practices for these common attack vectors. The lack of dangerous functions, file operations, external HTTP requests, and critical or high-severity taint flows further reinforces this positive assessment.
However, a significant concern arises from the 50% of output operations that are not properly escaped. This leaves the plugin vulnerable to Cross-Site Scripting (XSS) attacks, where malicious scripts could be injected into the application through user-provided input that is then displayed without proper sanitization. Additionally, the complete absence of nonce and capability checks across all entry points, though currently with a zero attack surface, represents a potential future risk. If new functionalities were to be added that introduce such entry points, they would be inherently unprotected against CSRF and unauthorized actions.
The plugin's vulnerability history, showing zero known CVEs, is an excellent indicator of its security track record. This suggests a history of responsible development and maintenance. Despite the existing output escaping and missing authorization checks concerns, the current lack of exploitable history and zero attack surface at entry points makes the immediate risk relatively low. Nonetheless, addressing the unescaped output is crucial to prevent potential XSS vulnerabilities.
Key Concerns
- Unescaped output detected
- No nonce checks on entry points
- No capability checks on entry points
Login Mandatory Pages Security Vulnerabilities
Login Mandatory Pages Code Analysis
Output Escaping
Data Flow Analysis
Login Mandatory Pages Attack Surface
WordPress Hooks 5
Maintenance & Trust
Login Mandatory Pages Maintenance & Trust
Maintenance Signals
Community Trust
Login Mandatory Pages Alternatives
wps-safe-logout
wps-safe-logout
This plugin will not allow the user to access login pages after logout when press the browser back button
Custom Login Page Customizer
login-customizer
Custom Login Customizer allows you to easily customize your admin login page, straight from your WordPress Customizer!
Custom Login Page Customizer
colorlib-login-customizer
Customize your WordPress login page with live preview. Change logo, background, colors, and form styling without coding.
Admin Custom Login
admin-custom-login
Customize Your WordPress Login Screen Amazingly - Add Own Logo, Add Social Profiles, Login Form Positions, Background Image Slide Show
Branda – White Label & Branding, Free Login Page Customizer
branda-white-labeling
White label & rebrand your login page & WordPress dashboard. Customize system emails & get everything to rebrand WordPress with Branda.
Login Mandatory Pages Developer Profile
1 plugin · 10 total installs
How We Detect Login Mandatory Pages
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/login-mandatory-pages/images/lmp.png/wp-content/plugins/login-mandatory-pages/css/ls.cssHTML / DOM Fingerprints
lr_setting_forminner-wrapsectionbutton-sectionname="pages_for_lr[]"name="message_for_lr"name="button_link_for_lr"